Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2463-rh88-r3gg

Опубликовано: 04 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal services and metadata endpoints, allowing the server to issue POST requests to restricted resources.

Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal services and metadata endpoints, allowing the server to issue POST requests to restricted resources.

EPSS

Процентиль: 24%
0.00313
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.4
nvd
14 дней назад

Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal services and metadata endpoints, allowing the server to issue POST requests to restricted resources.

EPSS

Процентиль: 24%
0.00313
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-918